Sync Claude Context - ensure agent files are up to date

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed project-context maintenance workflow with no malware signals, though users should expect it to read and update Claude-related project context files.

Install this if you want an agent to audit and refresh Claude project context files. Before running it, be aware it may read broad project structure and update project documentation, skills, and Claude memory; review the resulting git diff, especially if your repository contains private architecture notes or personal local Claude context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises itself for very common phrases such as "sync", "catch up", and "bring yourself up to speed," which makes it likely to activate in many normal conversations. Because the skill then performs broad repository inspection and proposes file updates, an overly broad trigger can cause unexpected autonomous actions and context changes when the user did not clearly request this specific workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal